CVE-2026-35273 | OraclePeopleSoft | RCE
| Field | Details |
|---|---|
| Vulnerability | CVE-2026-35273 |
| Summary | Unauthenticated remote code execution in the Oracle PeopleSoft Enterprise PeopleTools “Updates Environment Management” component (EMHub), rated CVSS 9.8 CRITICAL. Exploited in the wild as a zero-day (May 27 - June 9, 2026) by ShinyHunters (UNC6240) before Oracle’s June 10, 2026 out-of-band alert; on CISA KEV (added 2026-06-12, ransomware-linked). Remediation: apply Oracle’s out-of-band fix (via the My Oracle Support Patch Availability Document) plus the recommended mitigations. |
| Type / CWE | Unauthenticated remote code execution (RCE) / full server takeover. Primary weakness per NVD, CVE.org, and CISA KEV: CWE-306 Missing Authentication for Critical Function (the EMHub critical function is reachable without authentication). Note a framing nuance, not a contradiction: the in-the-wild exploit mechanism has been described as Server-Side Request Forgery (CWE-918) chained to insecure XMLDecoder deserialization (CWE-502); authoritative classifiers assign only CWE-306. |
| Affected Products & Versions | Oracle PeopleSoft Enterprise PeopleTools, component Updates Environment Management (Environment Management Hub / PSEMHUB). Supported affected versions per Oracle and NVD: 8.61 and 8.62. Oracle states untested earlier/unsupported releases are “likely” also affected (true lower bound undefined). Oracle also notes PeopleSoft Enterprise Applications customers running affected PeopleTools “may also be affected.” No version is listed as explicitly NOT affected beyond the fix shipped in the out-of-band response. |
| Severity & Exploitability | CVSS v3.1 base 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (scored by Oracle; mirrored on NVD). Plain-English: remote over HTTP/HTTPS (AV:N), low complexity (AC:L), no credentials (PR:N, unauthenticated), no user interaction (UI:N), Scope Unchanged (S:U). Confidentiality, Integrity, and Availability all HIGH. CVSS v4.0: not published (NVD “assessment not yet provided”; Oracle scores with CVSS v3.1 only). Exploitability is maximal: remote, unauthenticated, low-complexity, no interaction. |
| Description | NVD/Oracle verbatim: “Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).” Oracle alert: “This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. … If successfully exploited, this vulnerability may result in remote code execution.” Plain-English: any attacker who can reach the PeopleSoft Environment Management Hub HTTP(S) service can take over the underlying server with no login and no interaction. Public PoC status: none confirmed in primary sources as of mid-June 2026 (its absence has been reported); the absence of a PoC does not reduce risk given active in-the-wild exploitation. |
| Root Cause & Exploitation | Root cause: the Environment Management Hub (PSEMHUB) exposes critical functionality without authentication (CWE-306). The observed exploit mechanism has been reported as SSRF (CWE-918) against the unauthenticated EMHub endpoints, chained to insecure XMLDecoder deserialization (CWE-502) for code execution. Vulnerable endpoints: /PSEMHUB/hub and /PSIGW/HttpListeningConnector.Execution flow (per reported detection guidance): 1. Attacker sends a crafted unauthenticated HTTP(S) request to /PSIGW/HttpListeningConnector and/or /PSEMHUB/hub, embedding loopback/internal addresses (127.0.0.1, localhost, ::1, internal ranges) in headers/parameters to perform SSRF and bypass access controls.2. The exploit coerces the host into writing or referencing crafted .xml files under <docroot>/envmetadata/data/environment/.3. On application restart, those .xml files are processed via XMLDecoder, achieving RCE.4. Attackers drop unexpected .jsp webshells under <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/.Representative payload: no raw HTTP exploit request or PoC body was published. The closest public artifact is the SSRF indicator (requests to /PSIGW/HttpListeningConnector containing loopback/internal IPs in headers/params). Inferred: outbound SMB (TCP/445) coercion to capture Windows machine-account NetNTLM hashes has been reported and is mechanism-plausible but campaign-dependent. |
| Impact & Significance | All impacts HIGH (C:H/I:H/A:H), Scope Unchanged. A successful unauthenticated attacker gains code execution on the underlying server and can read, modify, or destroy data and disrupt availability (“takeover of PeopleSoft Enterprise PeopleTools,” per CISA KEV). The CVSS vector itself bounds documented impact to the vulnerable component/host (S:U); it does not assert an authorization-boundary crossing, though observed campaigns chained RCE into broader network compromise. Why it matters: PeopleSoft is widely deployed for enterprise HR/ERP and student-information systems, and many instances are internet-facing; the actively abused entry points (/PSEMHUB/*, /PSIGW/HttpListeningConnector) make exposed, unpatched 8.61/8.62 hosts high-value targets. Higher education was the dominant victim sector. |
| Threat Activity / Abuse Scenarios | Exploited in the wild as a zero-day before any patch existed. Active exploitation May 27 - June 9, 2026 has been attributed to UNC6240, publicly known as ShinyHunters (financially motivated, data-theft and extortion / data-leak-site focused; attribution as high-level context only). It was reported that 100+ organizations were notified as potentially affected, roughly 68% higher-education institutions; the actor’s claim of ~300 compromised instances is actor-sourced and not independently verified. CISA KEV: added 2026-06-12, knownRansomwareCampaignUse = “Known” (verified from the CISA KEV JSON feed, catalogVersion 2026.06.16). Realistic abuse: (1) unauthenticated RCE/server takeover via an exposed EMHub/Integration Broker endpoint; (2) persistence via webshell/XMLDecoder and internal recon; (3) mass exfiltration of HR/ERP/student data followed by extortion. Campaign-specific actor C2/tooling IOCs are out of scope here (see threat-intel References). |
| Detection & Hunting | Log sources: PeopleSoft web server / application logs, reverse-proxy / WAF logs, host file-system telemetry, and network egress logs. - Web/proxy logs: hunt unauthenticated external requests to /PSEMHUB/hub, /PSEMHUB/*, and /PSIGW/HttpListeningConnector from untrusted source IPs. Inferred: any successful external hit to these EMHub/Integration Broker paths from outside trusted ranges is suspicious because the function should not be unauthenticated-reachable.- SSRF pattern (reported): requests to these endpoints containing loopback ( 127.0.0.1, localhost, ::1) or internal/private IP ranges in headers or parameters.- Host artifacts (observed): unexpected .jsp files under <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/; unauthorized files under .../PSEMHUB.war/envmetadata/transactions/; unexpected directories named logs, persistantstorage, or scratchpad under PSEMHUB paths; recently created/modified .xml files under <docroot>/envmetadata/data/environment/ (potential XMLDecoder persistence); access to psappsrv.cfg (credential-extraction target, as reported).- Network: Inferred: monitor outbound SMB ( TCP/445) from PeopleSoft servers to untrusted destinations (mechanism-plausible NetNTLM coercion; also reported).- Vendor signatures (SSRF classification): IPS filter 1012580 “Oracle PeopleSoft PeopleTools SSRF Vulnerability”; Deep Discovery Inspector rule 5855 “Peoplesoft PeopleTools Environment Management Hub (PSEMHUB) SSRF Exploit”. Oracle’s advisory publishes no IPS/IDS signatures. |
| IOCs & Indicators | No vendor published a deterministic generic exploit-payload signature (canonical request body / magic bytes) for this CVE in primary sources; the reliable generic indicators are behavioral: - External/unauthenticated HTTP(S) requests to /PSEMHUB/hub, /PSEMHUB/*, or /PSIGW/HttpListeningConnector- Requests to those endpoints containing loopback ( 127.0.0.1, localhost, ::1) or internal/private IP ranges in headers/parameters (reported SSRF-style abuse)- Newly created server-side .jsp / .xml files under the PSEMHUB web app and envmetadata directories after such requests- Oracle’s advisory provides no IOCs - Note: campaign-specific atomic IOCs (actor C2 IPs, masquerade domains, MeshCentral/meshagent hashes) have been reported but are out of scope here; see threat-intel References. |
| MITRE ATT&CK | No official ATT&CK mapping exists in the authoritative CVE record (Oracle CNA + CISA-ADP Vulnrichment) or CISA KEV, which carry CWE-306 and KEV/SSVC metrics only. Inferred: T1190 Exploit Public-Facing Application (initial access via the internet-facing EMHub HTTP endpoint); T1190 has also been cited in public reporting. Other ATT&CK IDs in reporting (e.g. T1133, T1021, T1110, T1083, T1041) describe the ShinyHunters post-exploitation chain and are campaign-dependent, not intrinsic to this CVE. |
| Mitigation & Status | Patched (out-of-band) plus mitigations. Oracle published an out-of-band Security Alert on 2026-06-10 (advisory alert-cve-2026-35273.html; announced on the Oracle Security blog), separate from the quarterly cycle. The alert ships recommended mitigations (“We consider implementation of the recommended mitigations to be a high-priority risk reduction measure”) and directs customers to a Patch Availability Document (login-gated, on My Oracle Support / support.oracle.com) that, per the alert, contains “mitigation information and installation instructions” for the affected 8.61/8.62 releases, i.e. a fix is delivered through that document. Exact fixed PeopleTools build IDs are not in the public alert (they live in the login-gated document). Public reporting references “CPU187” as the patch-availability document; it is not named in Oracle’s primary alert and is a document pointer, not a fixed build number, so confirm the actual patched build in the login-gated document. Early “mitigations only” reporting reflects the initial-disclosure snapshot.Workarounds / hardening (reported): disable the EMHub service in multi-server deployments / remove PSEMHUB where not required in single-server deployments; block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector; avoid internet exposure of EMHub; hunt per the Detection row. CISA KEV due date: 2026-06-15 (accelerated, under BOD 26-04; already passed as of 2026-06-17). Solution status: fix available via the My Oracle Support Patch Availability Document (per Oracle’s Security Alert), alongside mitigations; confirm the exact patched build for your deployment in that document. |
| References | - https://nvd.nist.gov/vuln/detail/CVE-2026-35273 - https://www.oracle.com/security-alerts/alert-cve-2026-35273.html - https://blogs.oracle.com/security/security-alert-cve-2026-35273-released - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273 - https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json - https://www.cisa.gov/news-events/alerts/2026/06/12/cisa-adds-one-known-exploited-vulnerability-catalog - https://www.cve.org/CVERecord?id=CVE-2026-35273 - https://github.com/advisories/GHSA-25mw-359m-f6rj - https://support.oracle.com - https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit - https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/ - https://socradar.io/blog/cve-2026-35273-oracle-peoplesoft-peopletools/ - https://socprime.com/active-threats/cve-2026-35273-oracle-peoplesoft-zero-day-exploited-in-the-wild/ - https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ - https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html - https://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/ - https://www.securityweek.com/oracle-addresses-peoplesoft-vulnerability-amid-reports-of-zero-day-attacks/ - https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/ - https://arcticwolf.com/resources/blog/critical-oracle-peoplesoft-vulnerability-actively-exploited-in-shinyhunters-campaign/ |